8 Novell Access Manager 3.1 SP3 Installation Guide
11 Migrating from iChain to Access Manager 133
11.1 Understanding the Differences between iChain and Access Manager . . . . . . . . . . . . . . . . . 133
11.1.1 Component Differences. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133
11.1.2 Feature Comparison . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134
11.2 Planning the Migration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 135
11.2.1 Possible Migration Strategies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 135
11.2.2 Outlining the Migration Requirements for Each Resource. . . . . . . . . . . . . . . . . . . . 142
11.3 Migrating Components. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 144
11.3.1 Setting Up the Hardware and Installing the Software . . . . . . . . . . . . . . . . . . . . . . . 144
11.3.2 Using an L4 Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 145
11.3.3 Configuring the Identity Server for Authentication . . . . . . . . . . . . . . . . . . . . . . . . . . 145
11.3.4 Configuring System and Network Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147
11.3.5 Migrating the First Accelerator. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151
11.3.6 Enabling Single Sign-On between iChain and Access Manager. . . . . . . . . . . . . . . 158
11.3.7 Migrating Resources with Special Configurations . . . . . . . . . . . . . . . . . . . . . . . . . . 161
11.3.8 Moving Staged Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
11.3.9 Removing iChain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172
A Troubleshooting Installation and Upgrade 175
A.1 Troubleshooting a Windows Administration Console Installation. . . . . . . . . . . . . . . . . . . . . . 175
A.2 Troubleshooting a Windows SSL Renegotiation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176
A.3 Troubleshooting an Identity Server Import and Installation . . . . . . . . . . . . . . . . . . . . . . . . . . 177
A.3.1 The Identity Server Fails to Import into the Administration Console . . . . . . . . . . . . 177
A.3.2 Reimporting the Identity Server. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
A.3.3 Check the Installation Logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178
A.4 Troubleshooting a Linux Access Gateway Appliance Installation . . . . . . . . . . . . . . . . . . . . . 179
A.4.1 Some of the New Hardware Drivers or Network Cards Are Not Detected during
Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
A.4.2 After Reinstalling the Access Gateway, SSL Fails . . . . . . . . . . . . . . . . . . . . . . . . . 180
A.4.3 Reverting to an Earlier Snapshot of the Access Gateway Appliance Can Cause Multiple
Crashes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180
A.4.4 Manually Configuring a Network Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181
A.4.5 Manually Setting and Deleting the Default Gateway . . . . . . . . . . . . . . . . . . . . . . . . 182
A.4.6 Manually Configuring the Hostname, Domain Name, and DNS Server. . . . . . . . . . 182
A.4.7 Verifying Component Installation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183
A.4.8 Signature Error in SLES 11 Network Mode of Installation. . . . . . . . . . . . . . . . . . . . 184
A.5 Troubleshooting the Access Gateway Service Installation. . . . . . . . . . . . . . . . . . . . . . . . . . . 184
A.5.1 Troubleshooting the Linux Access Gateway Service Installation . . . . . . . . . . . . . . 184
A.5.2 Troubleshooting the Windows Access Gateway Service Installation. . . . . . . . . . . . 184
A.6 Troubleshooting the SSL VPN Installation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 185
A.6.1 Manually Uninstalling the Enterprise Mode Thin Client . . . . . . . . . . . . . . . . . . . . . . 185
A.6.2 SSL VPN Health Status Is Yellow after an Upgrade . . . . . . . . . . . . . . . . . . . . . . . . 186
A.7 Troubleshooting the Access Gateway Import . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 186
A.7.1 Repairing an Import. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 186
A.7.2 Triggering an Import Retry. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 187
A.7.3 Fixing Potential Configuration Errors on the Access Gateway Appliance . . . . . . . . 189
A.7.4 Troubleshooting the Import Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 189
A.8 Troubleshooting an Access Gateway Appliance Upgrade. . . . . . . . . . . . . . . . . . . . . . . . . . . 194
A.8.1 After You Migrate from SLES 9 to SLES 11, the Health Status Indicates That the
Embedded Service Provider Cannot Find the Keystores . . . . . . . . . . . . . . . . . . . . 194
A.8.2 Embedded Service Provider Issues After Upgrading . . . . . . . . . . . . . . . . . . . . . . . 195
A.8.3 Proxy Stops Responding after Trying to Upgrade with the Wrong Upgrade RPM . 196
A.8.4 Pending Commands After an Upgrade . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 196
A.8.5 After You Upgrade to Version 3.1, the New Alerts for Auditing Do Not Appear . . . 196